GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,468 advisories
Filter by severity
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
High
CVE-2026-76839
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
High
CVE-2026-76846
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
Moderate
CVE-2026-85717
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
Moderate
CVE-2026-85720
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient...
Moderate
Unreviewed
CVE-2026-89064
was published
Sep 17, 2026
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the...
High
Unreviewed
CVE-2026-92759
was published
Sep 16, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco...
Critical
Unreviewed
CVE-2026-20234
was published
Sep 16, 2026
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for...
Moderate
Unreviewed
CVE-2026-92133
was published
Sep 16, 2026
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-92256
was published
Sep 16, 2026
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-76871
was published
Sep 16, 2026
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-76854
was published
Sep 16, 2026
Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure...
High
Unreviewed
CVE-2026-76857
was published
Sep 16, 2026
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in...
High
Unreviewed
CVE-2026-76859
was published
Sep 16, 2026
IBM Verify Identity Access containers may not apply management password change operations correctly.
Critical
Unreviewed
CVE-2026-11921
was published
Sep 15, 2026
Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the...
Moderate
Unreviewed
CVE-2026-91982
was published
Sep 15, 2026
Description
When ZooKeeper authentication is configured, Storm deliberately retains
`storm...
Critical
Unreviewed
CVE-2026-82434
was published
Sep 14, 2026
Description
`getNimbusConf` returned the complete daemon configuration without redaction after...
Moderate
Unreviewed
CVE-2026-82433
was published
Sep 14, 2026
Insufficiently Protected Credentials vulnerability in Apache Syncope.
Audit events, when sent to...
Moderate
Unreviewed
CVE-2026-75015
was published
Sep 14, 2026
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN...
High
Unreviewed
CVE-2026-82786
was published
Sep 14, 2026
CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of...
Moderate
Unreviewed
CVE-2026-81861
was published
Sep 11, 2026
rclone: http backend forwards custom/auth headers to a different host on redirect
Low
CVE-2026-88013
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
High
CVE-2026-59158
was published
for
nuxt-ollama
(npm)
Sep 9, 2026
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an...
Moderate
Unreviewed
CVE-2026-81381
was published
Sep 8, 2026
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to...
High
Unreviewed
CVE-2026-77909
was published
Sep 8, 2026
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2026-64918
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API